If your data is on the dark web, it’s probably only a matter of time before it’s abused for fraud or account hijacking. Here’s what to do.
Viral Vaghela discovered an SQL injection vulnerability in Parsl, a parallel scripting library for Python. For the stable distribution (trixie), this problem has been fixed in version 2025.01.13+ds-1+deb13u1. We recommend that you upgrade your python-parsl packages.
Version 2.9.3 – 2025-12-30 Security: Fixed ANSI sequence injection (GHSA-59pp-r3rg-353g / CVE-2025-67746) Fixed COMPOSER_NO_SECURITY_BLOCKING env var not being respected for updates done via the install command, and added –no-security-blocking flag to install as well (#12677)
New upstream release (147.0)
Update to 2.69.0
Update to Upstream version 0.1.2 – https://github.com/complytime/complyctl/releases/tag/v0.1.2
Version 2.9.3 – 2025-12-30 Security: Fixed ANSI sequence injection (GHSA-59pp-r3rg-353g / CVE-2025-67746) Fixed COMPOSER_NO_SECURITY_BLOCKING env var not being respected for updates done via the install command, and added –no-security-blocking flag to install as well (#12677)
https://security-tracker.debian.org/tracker/DSA-6099-1
https://security-tracker.debian.org/tracker/DSA-6098-1
An update that solves one vulnerability and contains one feature can now be installed.
An update that solves one vulnerability and contains one feature can now be installed.
An update that solves one vulnerability and contains one feature can now be installed.
An update that solves one vulnerability and contains one feature can now be installed.
An update that solves one vulnerability can now be installed.
Google Guest Agent could be made to crash if it received specially crafted network traffic.
Several security issues were fixed in PHP.
Several security issues were fixed in libheif.
Update to 143.0.7499.192 * High CVE-2026-0628: Insufficient policy enforcement in WebView tag * Enable control flow integrity support for x86_64/aarch64 * Enable build for epel10.1
This update adds a patch to fix CVE-2025-56225, a flaw in the bundled version of fluidsynth.
MGASA-2026-0006 – Updated zlib packages fix security vulnerability
MGAA-2026-0004 – Updated nvidia470 packages fix bug
Update to 143.0.7499.192 * High CVE-2026-0628: Insufficient policy enforcement in WebView tag * Enable control flow integrity support for x86_64/aarch64 * Enable build for epel10.1
Backport fix for CVE-2025-22921
Version 1.0.21 This point release includes all the changes from 1.0.20-stable, which include a security fix for the crypto_core_ed25519_is_valid_point() function, as well as two new sets of functions: The new crypto_ipcrypt_* functions implement mechanisms for securely
Backport fix for CVE-2025-64512 / GHSA-wf5f-4jwr-ppcp
https://security-tracker.debian.org/tracker/DSA-6097-1
MGASA-2026-0005 – Updated libpcap packages fix security vulnerability
MGASA-2026-0004 – Updated sodium packages fix security vulnerability
MGASA-2026-0003 – Updated curl packages fix security vulnerabilities
MGASA-2026-0002 – Updated wget2 packages fix security vulnerability
A security issue was discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. For the oldstable distribution (bookworm), this problem has been fixed in version 143.0.7499.192-1~deb12u1.
MariaDB 10.11.15 Release notes: server/10.11/10.11.15
https://security-tracker.debian.org/tracker/DSA-6096-1
Reusing passwords may feel like a harmless shortcut – until a single breach opens the door to multiple accounts
An update that solves one vulnerability can now be installed.
An update that solves one vulnerability can now be installed.
An update that solves one vulnerability can now be installed.
Several security issues were fixed in Tornado.
GnuPG could be made to crash or run programs if it received specially crafted network traffic.
GnuPG could be made to crash or run programs if it received specially crafted network traffic.
